Sensitive research systems thread that needle by giving remote access to researchers with the data in the control and supervision of the responsible organization. Strong internal data access controls and data siloing alongside strict verified extraction routines. Specifically: limited project-dedicated DB access, full logging of data interactions, and full lockouts/freezes if something feels off.
‘The five safes’ is a good presentation from the NHS(?) a decade ago covering the approaches.
Data publishing restrictions around health data aren’t reckless. Modern computing and digital permanence mean we have to be extra cautious.